Live data from Hacker News

Some observations on the final text of the European Digital Identity framework

blog.xot.nl

151–153 of 153 posts

Re: Some observations on the final text of the European Digital Identity framework

#151

Earlier quoted context omitted.

an this is why a EU wide system is needed. I hold 3 digital identities (Spain, Italy and Sweden) and, believe me, it's not fun.

At least your Spanish DNIe contains an X.509 certificate you can access via PKCS#11 that Just Works, both for authentication and signature. You can even use it for SSH!

Spain invested on a standard infrastructure (client-side certificates) back in the days (early 2000 ?) and I am amazed by how simple, how well it works and how nobody else has thought about doing the same anywhere else (to my knowledge). Well done Spain, at least on this.

Re: Some observations on the final text of the European Digital Identity framework

#152
post #148

Earlier quoted context omitted.

> When it comes to certificate authorities, you don't even need to modify the browser or OS because they already allow you to add and remove authorities. The main reason people don't tend to do that is because they have no reason to. They're already starting to make it more difficult. Look at what's happening with DoH where it's harder and harder to choose how your DNS queries get done and you get steered to CloudFla…

> They're already starting to make it more difficult. Look at what's happening with DoH where it's harder and harder to choose how your DNS queries get done and you get steered to CloudFlare (who are pretty low on my list of entities I want to trust) instead. Now that browsers have mostly succeeded in forcing HTTPS everywhere, expect them to start turning the screws. DoH doesn't interfere with your ability to choose…

> DoH doesn't interfere with your ability to choose your own DNS provider.

It may not make it impossible but it makes it harder. You need a provider that supports DoH, and your browser will ignore your OS-wide DNS setting. Previously your default DNS provider would be an ISP that you'd picked; now the default is whoever's most profitable for your browser maker (you might say you pick your browser, but there's less real choice there than there is for ISPs, at least where I live).

> As far as I'm aware, no one has suggested that DoH should be mandatory. It is a sensible default that improves the privacy and security of most users, but a user who decides that they do not want to use DoH can simply opt out in the settings. Likewise, HTTPS is not mandatory either, and browsers will not prevent users from accessing unsecure sites. They will however warn users to make sure they are aware of the risks.

They won't do it all at once, but they're making it harder and harder to access non-HTTPS sites. It's gone from a clear warning to a block page where accessing the HTTP version requires multiple clicks on tiny text; the next step will be to make it require a config tweak to even get that tiny text at all, and then they'll say that their telemetry conveniently shows few people are using that config tweak (because who could imagine that the kind of people who would don't trust their browser maker would disable telemetry) so they're removing it. We've seen this whole playbook before. It'll be the same for DoH.

> A FoI request is just asking the government to give you information. They will never intentionally give you anything they do not want you to have. FoI laws tend to contain enough exceptions to cover any situation, but even if you should legally receive the information, there is nothing you can realistically do to make them provide it to you.

Governments are accountable to their citizens, not just in theory but in cultural practice, which is what really matters. If you get a bogus response to an FoI request then you can complain to your representatives, and if your representatives don't respond then you can vote them out. But more importantly, the clerk handling your request knows that their duty is to you, not their shareholders, and will generally act accordingly. And if they don't, there's a whole culture of whistleblowers, investigative journalists, activist judges and so on.

None of that exists for a private company CA where they're working for their shareholders and no-one expects them to do otherwise. Frankly even if it did leak out that a CA had refused to issue a certificate to someone who they just didn't like, it wouldn't even be a scandal unless you were lucky enough to catch the right moment where there was a social movement supporting that particular kind of person.

Re: Some observations on the final text of the European Digital Identity framework

#153
post #148

Earlier quoted context omitted.

> When it comes to certificate authorities, you don't even need to modify the browser or OS because they already allow you to add and remove authorities. The main reason people don't tend to do that is because they have no reason to. They're already starting to make it more difficult. Look at what's happening with DoH where it's harder and harder to choose how your DNS queries get done and you get steered to CloudFla…

> They're already starting to make it more difficult. Look at what's happening with DoH where it's harder and harder to choose how your DNS queries get done and you get steered to CloudFlare (who are pretty low on my list of entities I want to trust) instead. Now that browsers have mostly succeeded in forcing HTTPS everywhere, expect them to start turning the screws. DoH doesn't interfere with your ability to choose…

Missed one important part in my other reply:

> As far as I'm aware, browser vendors do not benefit from users using HTTPS everywhere. They encourage its use because it is generally beneficial to users.

Google (which is to say DoubleClick), which funds the majority of browsers, has a huge financial interest in HTTPS. They make their money on ad tracking, and it suits them to put a moat around that; privacy initiatives help them by making it harder for any new competitors to get hold of the same information they built their business on.

Post reply on HN